VYPR
breachPublished Jun 19, 2026· Updated Jun 24, 2026· 10 sources

Klue Supply Chain Attack Compromises Salesforce Data of Cybersecurity Firms Huntress and Recorded Future

A supply chain attack on competitive intelligence platform Klue has compromised Salesforce instances belonging to its customers, including cybersecurity firms Huntress and Recorded Future, with data exfiltration attributed to the emerging Icarus extortion group.

A supply chain attack targeting Klue, a competitive intelligence platform, has compromised Salesforce instances belonging to its customers, including cybersecurity firms Huntress and Recorded Future. The attackers exfiltrated customer relationship management (CRM) data from the affected Salesforce environments, highlighting the cascading risk of supply-chain compromises when third-party platforms hold privileged integrations with security vendors.

The attack began on June 11 and affected systems associated with software platform integrations. The hackers connected to Klue’s backend servers and executed unauthorized commands, pushing a code update to harvest OAuth tokens for customers’ Klue integrations. Klue notified customers of the incident on June 12, warning that it had deactivated OAuth tokens for all customers and disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack.

According to ReliaQuest, the hackers abused the Salesforce REST API to exfiltrate large volumes of CRM data over a 24-hour window, “including a concentrated burst of nearly a thousand queries in 15 minutes and sustained extraction windows lasting over 6 hours”. On June 17, Salesforce disabled the Klue Battlecards app integration, warning that it “detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app’s connection to Salesforce”.

On Thursday, both Huntress and Recorded Future confirmed that they were among the companies affected by the supply chain attack. “The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging. No threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry we collect was affected,” Huntress said. Recorded Future noted, “While our investigation is ongoing, we believe the impact was limited to business data fields stored in our Salesforce database, such as client contact names and email addresses. Certain business contract information may also have been potentially included in the impacted data.”

The incident was limited to the Klue-Salesforce integration and the attackers did not access any systems belonging to or maintained by the two cybersecurity firms. Huntress noted that several other cybersecurity companies use Klue, but no other firm appears to have publicly disclosed impact from the attack. The attack follows the same pattern observed in previous Salesforce, Salesloft Drift, and Gainsight incidents, which have been attributed to ShinyHunters and UNC6395, but appears to have been mounted by a new threat actor.

Huntress said it received attempted extortion communication from a threat actor calling itself “Mr Brean”, who pointed to a Session Messenger ID associated with Icarus, an extortion group that emerged in April 2026. Icarus’ leak site has one entry from early May, with the data allegedly stolen from the victim already published (albeit no longer available), and another from June 16, which points to data stolen from Salesforce. “With those matching data points, we have high confidence that the Icarus actor is responsible for the Klue compromise and this supply chain attack,” Huntress says.

While it has shared details of the attack with its customers, Klue has not made a public announcement on the matter. SecurityWeek has emailed the company for a statement and will update this article if it responds. The incident underscores the growing threat of supply chain attacks targeting SaaS integrations, where a single compromised third-party platform can expose sensitive data across multiple high-value organizations, including those in the cybersecurity sector itself.

Salesforce has now disabled the Klue Battlecards app integration entirely, blocking new connections until further notice, after detecting unusual activity that may have allowed unauthorized access to a subset of customer data via the app's OAuth tokens. ReliaQuest's analysis reveals the Icarus actor used compromised legacy credentials to obtain OAuth tokens, then ran automated Python scripts that enumerated Salesforce object catalogs and bulk-queried CRM records for up to 24 hours, including a burst of nearly a thousand queries in 15 minutes. Huntress confirmed that some employees received extortion emails threatening data exposure, while Klue stated the incident was limited to third-party platforms and did not affect customer content stored within its own platform.

Huntress published a detailed account on June 18, describing the incident as a 'security domino effect' where a single compromised Klue integration credential cascaded into theft of customer data across connected platforms, including Salesforce. The attack timeline and technical details provided by Huntress offer new insight into how the Icarus group exploited the OAuth breach to exfiltrate data from multiple organizations.

The Icarus extortion group has now publicly claimed responsibility for the Klue breach on its data leak site, posting a message that pressures Klue and affected organizations to negotiate via the Session messaging platform to prevent data leaks. Additional victims have come forward, including Tanium, Jamf, Sprout Social, Gong, and Insurity, all confirming that their Salesforce data was stolen. Several of these organizations warned that the exfiltrated business contact information could be weaponized in follow-on phishing, social engineering, and extortion campaigns, urging heightened vigilance.

The list of affected organizations has grown to at least nine, with HackerOne, Jamf, OneTrust, Snyk, Tanium, Insurity, and Sprout Social joining Huntress and Recorded Future in confirming that attackers exfiltrated Salesforce CRM data including names, email addresses, job titles, and phone numbers. Gong also disclosed that its Klue integration was exploited to access internal licensed user data, though it clarified that call recordings and customer transcripts were not compromised. The threat actor Icarus has claimed responsibility on a Tor-based leak site and threatened to publish the stolen data on June 22 unless Klue and the affected companies negotiate.

The new article adds that ReliaQuest, Jamf, and Tanium were also affected, bringing the total to at least five cybersecurity firms. It also reveals that the Icarus extortion group set a June 22 deadline for Klue clients to respond before leaked data is published, and that non-cybersecurity firms Insurity and Sprout Social were impacted as well.

The new article expands the list of affected organizations to include HackerOne, Jamf, OneTrust, Snyk, Sprout Social, Insurity, Tanium, and Gong, bringing the total to at least nine victims. It also provides additional technical detail: the attackers executed nearly 1,000 Salesforce REST API queries in 15 minutes during peak activity, with sustained extraction windows lasting over six hours. Klue CEO Jason Smith publicly characterized the incident as a deliberate criminal act on June 22, and the company has engaged CrowdStrike for incident response while notifying law enforcement.

The Register reports that the victim list now includes at least a dozen cybersecurity and software vendors beyond the initial disclosures, among them Tanium, ReliaQuest, Jamf, Gong, HackerOne, Kudelski Security, Snyk, Insurity, and Sprout Social. Huntress shared the extortion email from the Icarus group, which was sent from a sender calling themselves 'mr bean' and demanded communication via Session within 48 hours. Researchers noted that IP addresses linked to the attackers originate from the Netherlands, France, and Ukraine, though these may be VPNs or Tor exit nodes, and no evidence has been found connecting Icarus to the previously active ShinyHunters group.

LastPass has now confirmed that its Salesforce environment was breached in the same Klue supply chain attack, with attackers using stolen OAuth tokens to access customer metadata including names, phone numbers, email addresses, and support case information. The password manager stated that its own products and customer vaults remained unaffected, but warned that the exposed data could be weaponized for targeted phishing and social engineering campaigns. LastPass has since revoked the compromised tokens, disabled its Klue integration, and notified law enforcement, while advising users to remain vigilant against unsolicited communications from the attacker-controlled domains baccarat.com.au, robinskitchen.com.au, and house.com.au.

LastPass has now joined the list of affected vendors, disclosing that attackers used OAuth tokens stolen from Klue to access customer data in its Salesforce environment, including names, phone numbers, email addresses, and support case records. The company emphasized that its core password vault infrastructure was not compromised, but warned that the exposed contact details could fuel targeted phishing and social engineering attacks against its customers.

Synthesized by Vypr AI